Vulnerability Description
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Virusscan Enterprise | <= 2.0.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94823
- http://www.securitytracker.com/id/1037433
- https://kc.mcafee.com/corporate/index?page=content&id=SB10181Vendor Advisory
- https://www.exploit-db.com/exploits/40911/
- http://www.securityfocus.com/bid/94823
- http://www.securitytracker.com/id/1037433
- https://kc.mcafee.com/corporate/index?page=content&id=SB10181Vendor Advisory
- https://www.exploit-db.com/exploits/40911/
FAQ
What is CVE-2016-8021?
CVE-2016-8021 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and exec...
How severe is CVE-2016-8021?
CVE-2016-8021 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8021?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Virusscan Enterprise.